Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
Remediation
References
https://snyk.io/vuln/SNYK-JS-POSTLOADER-2403737
Related Vulnerabilities
CVE-2022-25890 Vulnerability in npm package wifey
CVE-2020-7646 Vulnerability in npm package curlrequest
CVE-2019-13343 Vulnerability in maven package com.butor:portal
CVE-2023-26113 Vulnerability in npm package collection.js
CVE-2023-1454 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common